{
  "schemaVersion": 1,
  "asOf": "2026-09-01",
  "product": "MIRMC Product Studio",
  "classification": "enterprise-capable",
  "deploymentStatus": "source-defined-pending-production-verification",
  "certificationStatus": "not-certified",
  "governedEvidenceLineage": {
    "version": "1.0.0",
    "passportVersion": "1.1.0",
    "databaseVerifierVersion": "1.3-hardening",
    "stages": [
      "intent",
      "approval",
      "actor",
      "resource",
      "commit",
      "artifact",
      "runtime",
      "receipt"
    ],
    "appendOnly": true,
    "tamperEvident": true,
    "tenantScope": "organization",
    "correlationScope": "organization",
    "databaseVerification": "canonical-content-hash-recomputation",
    "databaseVerifierChecks": [
      "active-tenant-binding",
      "canonical-content-hash-recomputation",
      "predecessor-hash-continuity",
      "canonical-stage-order",
      "unique-stage-and-sequence",
      "chronological-monotonicity"
    ],
    "runtimeVerification": "commit-to-runtime-identity",
    "failClosed": true,
    "authorityBoundary": "evidence-never-grants-authority",
    "fourEyesBypass": false
  },
  "evidencePassport": {
    "states": ["verified", "partial", "unverified"],
    "verifiedRequires": [
      "complete-lineage",
      "continuous-hash-chain",
      "canonical-stage-order",
      "active-tenant-binding",
      "unique-sequence-positions",
      "chronological-monotonicity",
      "database-hash-recomputation",
      "application-database-agreement",
      "complete-runtime-identity",
      "commit-runtime-match"
    ],
    "freshnessStates": ["current", "aging", "historic", "unknown"],
    "grantsAuthority": false,
    "canPublishByPassportAlone": false,
    "canDeployByPassportAlone": false,
    "evidenceCanBypassFourEyes": false
  },
  "assurance": {
    "procurementEvidenceAvailable": true,
    "externalAssuranceComplete": false,
    "contractualSlaClaimed": false,
    "soc2Type2Claimed": false,
    "iso27001Claimed": false,
    "executedDpaClaimed": false,
    "contractualDataResidencyClaimed": false
  },
  "canonical": {
    "productStudio": "https://studio.mirmcsolutionweb.com/",
    "enterpriseAssurance": "https://mirmcsolutionweb.com/en/enterprise-assurance",
    "enterpriseEvidence": "https://mirmcsolutionweb.com/en/enterprise-evidence",
    "procurementReadiness": "https://mirmcsolutionweb.com/en/procurement-readiness",
    "trustCenter": "https://mirmcsolutionweb.com/en/trust",
    "operationalStatus": "https://mirmcsolutionweb.com/en/status",
    "lineageSchema": "https://mirmcsolutionweb.com/.well-known/mirmc-product-studio-lineage.schema.json",
    "passportSchema": "https://mirmcsolutionweb.com/.well-known/mirmc-product-studio-evidence-passport.schema.json"
  },
  "notClaims": [
    "A source commit is not proof of production deployment.",
    "A build artifact is not proof that production serves that artifact.",
    "Evidence does not grant execution, deployment or publication authority.",
    "MIRMC does not claim SOC 2 Type II or ISO/IEC 27001 certification without independent assurance.",
    "MIRMC does not claim an executed DPA, contractual SLA or contractual data-residency guarantee from source code alone."
  ],
  "disclaimer": "This manifest describes source-defined Product Studio assurance controls and their interpretation. Production status, external certification and contractual commitments require their own evidence and are never inferred from this file."
}
